Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjx3-mjph-w6x6

Опубликовано: 19 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulnerability. An attacker could perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. Exploitation could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices.

Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulnerability. An attacker could perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. Exploitation could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices.

EPSS

Процентиль: 42%
0.00203
Низкий

7 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7
nvd
около 3 лет назад

Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulnerability. An attacker could perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. Exploitation could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices.

CVSS3: 7
fstec
около 3 лет назад

Уязвимость системы хранения данных Cloud Mobility for Dell Storage, связанная с неправильной проверкой отзыва сертификата, позволяющая нарушителю выполнить атаку типа «человек посередине»

EPSS

Процентиль: 42%
0.00203
Низкий

7 High

CVSS3

Дефекты

CWE-295